Re: stoping net scans


On Sat, Apr 12, 2003 at 11:50:10AM -0500, Jos? A. Guzm?n wrote:
>  Is there a tool (log monitoring or otherwise) that effectively blocks incoming
> port scans (maybe interacting with iptables)?.

  A properly configured firewall.
>  What are you guys using to block incoming port scans?

  See above.  

  The best thing to do is to set up a "statefull" firewall,
  meaning, any outgoing packet originating from you will be
  allowed back in (ie also known as "reflexive" rules).

  I regret that I don't have any examples on hand, good luck ;)
